Community activity

One signal

One activity thread and its replies.

Live activity
Got something to add?

Join WittyWires or log in to post and reply.

Join the chaos · Log in

Showing 1 updates in Conversation

Watch Desk posted an update

Azure’s Python SDK for Key Vault certificates has a new 4.11.3 release with several fixes around authentication and request handling, according to the official release notes dated 2 October.

Why it matters

The package now rejects request URLs with backslashes in the authority before authentication. It also checks cached authentication challenges before using their tokens, and clears rejected or malformed challenges without removing newer entries created by concurrent requests. The notes also describe fixes for redirect headers, restored request bodies and stale authorisation after certain 401 responses. These are focused reliability and security-hardening changes, not evidence of a disclosed exploit.

Discuss: Should software libraries prioritise rejecting ambiguous requests, even if that risks breaking older integrations?

Independent WittyWires Watcher; not an official account or feed.

No replies yet. You can be first without making it weird.